This Privacy Policy (“Policy”) applies to users accessing HDI's digital platforms, managed by PT Harmoni Dinamik Indonesia (“HDI,” “we,” or “us”).
HDI complies with data protection laws in all jurisdictions where we operate, including:
Indonesia: Personal Data Protection Law No. 27 of 2022 (UU PDP).
Singapore: Personal Data Protection Act 2012 (PDPA).
Malaysia: Personal Data Protection Act 2010 (PDPA).
Philippines: Data Privacy Act of 2012 (RA 10173).
Hong Kong: Personal Data (Privacy) Ordinance (PDPO).
By using our platforms, you have read, understood, and consented to the processing of your Personal Data as described in this Policy.
In the event of conflicting interpretations between the Indonesian and English versions, the Indonesian version shall prevail in Indonesia, while the English version shall prevail in jurisdictions outside Indonesia.
Definitions
Personal Data: Any information that can identify an individual, either directly or indirectly.
HDI Platforms: Websites and digital systems operated by HDI, including HDI (www.hdi.com), HDI One (www.hdione.com), and other official channels.
Third-Party Partners: Service providers for payments, logistics, authentication, or mapping services that collaborate with HDI.
Member: Consumers who register or purchase products directly and officially through HDI without a minimum transaction requirement.
Enterpriser: A type of HDI membership governed by direct selling regulations or relevant industry associations, depending on the jurisdiction in which we operate.
Collection of Personal Data
Methods of Collection
We collect your Personal Data through:
Direct Collection: Information you provide when registering, transacting, or communicating with us.
Automatic Collection: Technical information gathered via cookies, activity logs, or similar technologies while you use our platforms.
Third-Party Sources: Information from trusted partners such as payment processors, logistics services, authentication (e.g., OTP), or mapping services.
Types of Personal Data Collected
We may collect the following data:
Identity Data: Full name, email, phone number, physical address, date of birth, gender, religion, marital status, and identification numbers (e.g., ID card or passport for Enterprisers).
Financial Data: Bank account details, tax identification number (if required), and payment records for transactions or commissions.
Technical Data: IP address, device type, geographic location, log files, and usage activities.
Communication Data: Information related to your communication preferences (email, SMS, WhatsApp, etc.).
Location Data: Your location for mapping or delivery services.
Data for AI Recommendation System: We use an AI-based recommendation system that may collect and process your transaction history, product types, quantities, and member ID. This data may be shared with a third-party AI service provider to offer relevant product recommendations.
Purpose of Collection
We collect data to:
Provide our services (order processing, user authentication, and account management).
Enhance user experience (location-based features, personalized communications, and AI-driven recommendations).
Comply with legal obligations and prevent fraud.
Monitor website traffic and performance for analytics purposes (e.g., daily/monthly visitor counts, conversion rates, and similar metrics).
Providing information about products, services, or special offers relevant to user preferences through various communication channels.
No Health Data Collected
We confirm that we do not collect, process, or store any health-related data at this time.
User Responsibility for Data Accuracy
Users are responsible for ensuring that any Personal Data provided to HDI is accurate, complete, and up to date. In the event of any changes, users must promptly update their Personal Data through mechanisms provided by HDI.
Legal Basis for Data Processing
We process Personal Data based on:
Consent: Given when you register or use our services.
Legal Obligations: Such as tax reporting or other regulatory requirements.
Legitimate Interests: For improving our services and protecting users.
Use of Personal Data
We use Personal Data to:
Deliver services (processing orders, managing accounts, and customer support).
Send important information, including service updates or promotions. You may opt out of promotional messages by following the “unsubscribe” instructions provided in such communications.
Ensure platform security and fraud prevention.
Process data for the AI-based recommendation system, which may involve third-party service providers.
Perform analytics on platform usage to monitor site performance.
Your Rights as a Data Subject
Access to Information
You have the right to obtain information about the basis and purpose of the request and use of your personal data.
Access
You have the right to access and request a copy of your Personal Data that we hold about you.
Rectification
You may complete, update, and/or rectify any inaccurate or incomplete Personal Data.
Withdraw Consent
You may withdraw your consent at any time, with the understanding that this may affect your ability to access certain services.
Manage Visibility
You have the right to manage the visibility of certain data via the HDI One portal, except for data considered essential to the network\'s operations.
Erasure
You may request the deletion of your Personal Data where permitted by applicable laws.
File Complaints
You may lodge a complaint with HDI or the relevant data protection authority regarding the processing of your Personal Data.
Procedure for Requests: To submit a request, you may email us at privacy@hdi.com or contact the relevant DPO (see Section 12). Please include your full name, contact information, and a brief description of the request. We may require proof of identity or additional documentation for verification before proceeding with your request.
Response to Data Subject Requests: We will respond to your request as soon as reasonably possible and, in any event, no later than thirty (30) calendar days from the date of receipt, unless local regulations require a different timeframe. If we require more time or cannot fulfill your request, we will inform you of the reasons for any delay or refusal.
Escalation Process: If you feel that your request has not been handled satisfactorily, you may contact our DPO (see Section 12) or lodge a complaint with the relevant data protection authority.
Data Sharing and Transfers
Internal Sharing
Your data may be shared internally within HDI for:
Sales Network Purposes: By default, your personal data, including transaction history, may be accessible to your upline. However, you can manage the visibility of certain data via the HDI One portal, except for data essential to the network\'s operations.
Service Operations: Customer support, data analysis, and platform improvements.
Sharing with Third Parties
We may share your Personal Data with trusted partners, such as:
Payment and logistics providers for transaction processing and deliveries.
Authentication services (e.g., OTP) to secure your account.
Mapping services for location-based features.
AI service providers to support our product recommendation system.
Analytics providers whose embedded code runs on our site to monitor traffic and performance (e.g., daily/monthly visitor counts, conversion rates, and similar metrics).
We do not sell or rent your Personal Data to third parties, and any sharing is strictly limited to the scope described in this Policy. All such third parties are required to maintain the confidentiality of your Personal Data and comply with applicable data protection regulations.
International Transfers
If your Personal Data is transferred outside Indonesia (for example, for logistics or other international service providers), HDI ensures that:
Transfers are conducted with adequate safeguards in compliance with UU PDP (e.g., standard contractual clauses).
The service providers in the destination country comply with local data protection laws (e.g., PDPA in Singapore, PDPO in Hong Kong).
Corporate Changes
In the event of a corporate restructuring, merger, acquisition, or sale of assets, the Personal Data we hold may be transferred as part of that process. We will ensure that any recipient remains bound by confidentiality obligations and processes Personal Data in compliance with applicable data protection regulations.
Data Security and Retention
Security Measures:
We employ encryption, role-based access controls, and regular audits to protect your data. We also conduct periodic internal training to enhance employee security awareness. HDI is ISO27001:2022 certified, reflecting our commitment to maintaining a robust, internationally recognized information security management system.
Retention Periods:
We retain data only as long as it is needed for the purpose for which it was collected or as required by local laws. After the retention period, data will be deleted or anonymized.
Use of Cookies and Similar Technologies
We use cookies to improve platform functionality and enhance user experience, including user authentication, delivering relevant content, and analyzing platform usage.
You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect platform functionality.
Data Breach Management
In the event of a data breach affecting your rights, we will promptly notify you and relevant authorities in accordance with applicable laws.
We will also take remedial actions to minimize any potential impact.
Changes to the Privacy Policy
This Policy may be updated to reflect changes in law, technology, or business practices.
If updates are material, we will display a pop-up notification when you log in to HDI's platform, allowing you to review such changes before continuing to use our services.
Any changes to this Privacy Policy will take effect once we post the revised Privacy Policy on this page: www.hdi.com/privacy.
Data Protection Officer (DPO) and Contact Information
Indonesia: Where required by UU PDP or subsequent regulations, a Data Protection Officer (DPO) will be appointed. You may reach the Indonesian DPO at: dpo-id@hdi.com.
Singapore: Pursuant to the PDPA, you may contact our Singapore DPO at: dpo-sg@hdi.com.
Philippines: Under the Data Privacy Act, you may contact our Philippine DPO at: dpo-ph@hdi.com.
Malaysia / Hong Kong: If required by local laws, we will provide a DPO contact at dpo-my@hdi.com or dpo-hk@hdi.com, or any other channel mandated by regulations.
For general inquiries, exercising your rights, or complaints, please contact:
Email: privacy@hdi.com
Children and Age Restrictions
Only individuals who are at least 18 years old are permitted to become HDI members. We do not accept membership registrations from individuals under the age of 18.
If we become aware that a member is under 18, we may take steps in accordance with applicable laws, including but not limited to suspending or closing the account.
Links to Third-Party Websites
HDI's platforms may contain links to third-party websites or services. This Privacy Policy does not extend to those external sites or services. We encourage you to review the privacy policies of any third-party site or service before providing any Personal Data.